SC-200 · Question #255
You have 50 Microsoft Sentinel workspaces. You need to view all the incidents from all the workspaces on a single page in the Azure portal. The solution must minimize administrative effort. Which…
The correct answer is A. Microsoft Sentinel - Incidents. Microsoft Sentinel - Incidents supports a feature called Microsoft Sentinel workspace manager and, more relevantly, the multi-workspace incidents view, which aggregates incidents from multiple Sentinel workspaces into a single unified page - exactly what the question requires…
Question
You have 50 Microsoft Sentinel workspaces. You need to view all the incidents from all the workspaces on a single page in the Azure portal. The solution must minimize administrative effort. Which page should you use in the Azure portal?
Options
- AMicrosoft Sentinel - Incidents
- BMicrosoft Sentinel - Workbooks
- CMicrosoft Sentinel
- DLog Analytics workspaces
How the community answered
(33 responses)- A88% (29)
- B3% (1)
- C3% (1)
- D6% (2)
Explanation
Microsoft Sentinel - Incidents supports a feature called Microsoft Sentinel workspace manager and, more relevantly, the multi-workspace incidents view, which aggregates incidents from multiple Sentinel workspaces into a single unified page - exactly what the question requires with minimal admin effort.
Why the distractors are wrong:
- B (Workbooks): Workbooks are for custom data visualization and reporting, not incident management or cross-workspace incident aggregation.
- C (Microsoft Sentinel - the overview/home page): This is the main Sentinel landing page showing dashboards and summaries, but it does not consolidate incidents across workspaces into a single actionable list.
- D (Log Analytics workspaces): This is the underlying data platform for Sentinel; it lists workspaces but doesn't provide an incident management view at all.
Memory tip: Think "Incidents live on the Incidents page" - the Microsoft Sentinel Incidents blade is purpose-built for incident triage and supports multi-workspace views natively. If the question involves viewing or managing incidents across workspaces with minimal effort, the answer will always point back to the Incidents page rather than any broader or more generic blade.
Topics
Community Discussion
No community discussion yet for this question.